CAP - A Context-Aware Framework for Detection and Analysis of Packed Malware

Muhammad Nouman Ahmed, Zafar Iqbal, Hassan Mahmood, Moiz Abdullah · 2024

The widespread use of packers to obfuscate and shield executable files makes it difficult for malware analysts to identify and analyze malicious samples. As packers implement more complex protective measures, developing advanced detection and analysis methods is crucial to stay ahead of cyber threats. This research is motivated by the requirement to examine the effectiveness of four well-known techniques: PEID Signatures, Import Hashing, Fuzzy Hashing, and Automatic YARA Signatures, which go beyond standard obfuscation defences. A dataset containing 3,089 samples, which consisted of 25 different packers, was collected. The best accuracy was obtained using a context-aware approach that included the findings from all four scripts, resulting in an astounding 96% detection rate. Using the proposed methods, packed malware samples can be detected more reliably. Moreover, a malware analyst can identify packed malware with minimal effort.

Read the paper · More papers on PaperTik